cmk policy 추가

"Sid": "cloudwatch", "Effect": "Allow", "Principal": { "Service": "logs.ap-northeast-2.amazonaws.com" }, "Action": [ "kms:Encrypt", "kms:Decrypt", "kms:ReEncrypt*", "kms:GenerateDataKey*", "kms:DescribeKey" ], "Resource": "*"